git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Replacing large blobs in git history

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 8, 2012, 21:22 UTC
Message-ID
<7vy5rabxe6.fsf@alter.siamese.dyndns.org>
In-Reply-To
<4F58D2CD.2050502@ira.uka.de>
Holger Hellmuth <hellmuth@ira.uka.de> writes:
Show 13 quoted lines
> On 07.03.2012 22:27, Ævar Arnfjörð Bjarmason wrote:
>> Does something other than git-fsck actually check whether the
>> collection of blobs you're getting from the remote when you clone have
>> sensible sha1's?
>>
>> What'll happen if he replaces that 550MB blob with a 0 byte blob but
>> hacks the object store so that it pretends to have the same sha1?
>
> This is something I tested once because of security concerns
> (i.e. what happens if a malicious intruder just drops something else
> into the object store) and if I remember correctly only git-fsck was
> able to spot the switch. But I didn't test cloning, only a few local
> operations.

Local operation that do not have to look at such a corrupt blob will not verify everything under the sun every time for obvious reasons.

An operation to transfer objects out of the repository (e.g. serving as the source of "clone" from elsewhere) will notice when it has to send such a corrupt object and you will be prevented from spreading the damage.

The same thing for a transfer in the reverse direction. When the other side tells us that it is giving us everything we asked, we still look at all the objects we received to make sure.

Previous: Holger HellmuthNext: Michael Haggerty
Message 5 of 6 in “Replacing large blobs in git history”
  1. Barry RobertsMar 6, 2012
  2. Neal KreitzingerMar 6, 2012
  3. Ævar Arnfjörð BjarmasonMar 7, 2012
  4. Holger HellmuthMar 8, 2012
  5. Junio C HamanoMar 8, 2012
  6. Michael HaggertyMar 7, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.